查看: 5321|回复: 31
收起左侧

[误报文件] (误报...)游戏启动程序

  [复制链接]
qynubf
发表于 2010-12-18 23:30:21 | 显示全部楼层 |阅读模式
本帖最后由 qynubf 于 2010-12-20 21:31 编辑

误报,金山区http://bbs.kafan.cn/thread-871274-1-1.html







http://www.virustotal.com/file-scan/report.html?id=9fd81afc8bdf18d9828f2647f511b9022b7aee184c0a809548c785d8a240bfe2-1292685533
一个游戏的启动程序,小红伞报毒,不敢玩,请高人帮忙分析一下。



http://virscan.org/report/bd88761bc274c3205f2a2b2a007c1668.html


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
蝉鸣时
发表于 2010-12-18 23:47:35 | 显示全部楼层
解压时提示“这个压缩文件格式未知或者数据已经被损坏”。


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
qynubf
 楼主| 发表于 2010-12-18 23:54:37 | 显示全部楼层
回复 2楼 蝉鸣时 的帖子

重新上传了
我是新手
发表于 2010-12-19 00:11:14 | 显示全部楼层
2010-12-19 08:10:00 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\system32\winspool.drv C:\WINDOWS\system32\winspool.drv
2010-12-19 08:10:00 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\system32\imm32.dll C:\WINDOWS\system32\imm32.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\Program Files\Common Files\Kingsoft\kiscommon\security\ksde\kisdcom.dll C:\Program Files\Common Files\Kingsoft\kiscommon\security\ksde\kisdcom.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\system32\uxtheme.dll C:\WINDOWS\system32\uxtheme.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\Program Files\Common Files\Kingsoft\kiscommon\kwsui.dll C:\Program Files\Common Files\Kingsoft\kiscommon\kwsui.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\Program Files\Common Files\Kingsoft\kiscommon\kswebshield.dll C:\Program Files\Common Files\Kingsoft\kiscommon\kswebshield.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_USERS\S-1-5-21-725345543-1035525444-1417001333-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\system32\MSCTF.dll C:\WINDOWS\system32\MSCTF.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\system32\MSCTFIME.IME C:\WINDOWS\system32\MSCTFIME.IME
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\system32\ddraw.dll C:\WINDOWS\system32\ddraw.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\system32\dciman32.dll C:\WINDOWS\system32\dciman32.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\system32\dinput.dll C:\WINDOWS\system32\dinput.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载全局钩子C:\WINDOWS\system32\dinput.dll C:\WINDOWS\system32\dinput.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\system32\dsound.dll C:\WINDOWS\system32\dsound.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\system32\dplayx.dll C:\WINDOWS\system32\dplayx.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\system32\d3drm.dll C:\WINDOWS\system32\d3drm.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\system32\msvfw32.dll C:\WINDOWS\system32\msvfw32.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5 HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE\SOFTWARE HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE\SOFTWARE
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe写注册表HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe写注册表HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe写注册表HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe写注册表HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication HKEY_LOCAL_MACHINE\Software\Kingsoft\KSBReg\6909E9F5\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe写注册表HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe写注册表HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe创建注册表键值HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\BNQ7820\5&36cf5044&0&10000080&01&05\Device Parameters HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\DISPLAY\BNQ7820\5&36cf5044&0&10000080&01&05\Device Parameters
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe发送消息C:\WINDOWS\explorer.exe C:\WINDOWS\explorer.exe
2010-12-19 08:10:22 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe发送消息C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\ctfmon.exe
2010-12-19 08:10:22 结束进程C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe
qynubf
 楼主| 发表于 2010-12-19 00:18:20 | 显示全部楼层
我是新手 发表于 2010-12-19 00:11
2010-12-19 08:10:00 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\WINDOWS\ ...

C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\Program Files\Common Files\Kingsoft\kiscommon\kwsui.dll C:\Program Files\Common Files\Kingsoft\kiscommon\kwsui.dll
2010-12-19 08:10:01 C:\Documents and Settings\Administrator\桌面\MoZunLogin.exe加载库文件C:\Program Files\Common Files\Kingsoft\kiscommon\kswebshield.dll C:\Program Files\Common Files\Kingsoft\kiscommon\kswebshield.d
怎么有金山啊?
viruskiller123
发表于 2010-12-19 00:27:20 | 显示全部楼层
经证实, 该文件为有毒文件
悟心之道
发表于 2010-12-19 08:24:16 | 显示全部楼层
比较烦要下N个文件不想玩
猪头大队
头像被屏蔽
发表于 2010-12-19 10:02:38 | 显示全部楼层
winrar不支持好压,放弃测试。
fatezero
发表于 2010-12-19 10:30:18 | 显示全部楼层
无法解压?
qynubf
 楼主| 发表于 2010-12-19 10:32:56 | 显示全部楼层
回复 8楼 猪头大队 的帖子

重新上传了RAR格式
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-9 13:40 , Processed in 0.135675 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表